PT-2020-19312 · Ge Healthcare · Apexpro Telemetry Server+3

Published

2020-01-24

·

Updated

2020-03-17

·

CVE-2020-6964

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ApexPro Telemetry Server versions 4.2 and prior CARESCAPE Telemetry Server version 4.2 and prior Clinical Information Center (CIC) versions 4.X and 5.X CARESCAPE Central Station (CSCS) versions 1.X and 2.X
Description The integrated service for keyboard switching in the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.
Recommendations For ApexPro Telemetry Server versions 4.2 and prior, consider restricting network access to the integrated service for keyboard switching until a fix is available. For CARESCAPE Telemetry Server version 4.2 and prior, restrict access to the keyboard switching service to prevent unauthorized input. For Clinical Information Center (CIC) versions 4.X and 5.X, limit network exposure of the affected service to minimize the risk of exploitation. For CARESCAPE Central Station (CSCS) versions 1.X and 2.X, disable the keyboard switching feature temporarily to prevent remote access without authentication.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6964

Affected Products

Apexpro Telemetry Server
Carescape Central Station
Carescape Telemetry Server
Clinical Information Center